arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

StallGrid:测量协议原生OT诱捕陷阱中互联网暴露的参与度

StallGrid: Measuring Internet-exposed Engagement in Protocol-Native OT Tarpits

Arthur Cordeiro, Casper Andersen, Emmanouil Vasilomanolakis

arXiv 2609.34708首次发表:更新:

发表机构

Technical University of Denmark(丹麦技术大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对OT/ICS协议无认证且补丁受限的现状,提出首个应用层诱捕陷阱StallGrid,利用Modbus异常码和IEC-104状态机停滞扫描器,在线验证其有效性和恶意流量相关性。

AI 中文摘要

运营技术系统面临扫描和协议特定攻击工具的暴露,其安全威胁可能导致物理过程中断,而非仅仅是数据泄露。传统的OT防御依赖于在严格补丁约束下的阻断和过滤,而诱捕陷阱通过持续的协议级交互延迟扫描器。Modbus TCP和IEC-104协议本身不携带任何认证或完整性保护。应用层诱捕陷阱,即在合法协议交换中停滞扫描器,已在IT和IoT协议中得到研究,但尚未针对OT/ICS,其会话语义(状态机、异常码)提供了IT/IoT所缺乏的停滞机会,且其补丁受限环境恰恰需要这种替代防御。我们提出StallGrid,据我们所知是首个针对OT/ICS的应用层诱捕陷阱,通过Modbus异常码\ exttt{0x05}/\ exttt{0x06}和延长在IEC-104连接状态机中的驻留来停滞扫描器。五种变体(三种Modbus TCP,两种IEC-104)同时在线运行24天,记录了6,709个会话,每个诱捕陷阱累计2,039个唯一IP,以及超过2,000小时的累计连接参与时间。GreyNoise富化将87%至97%的停滞时间归因于恶意标记的IP,而这些IP仅占连接地址的22%至30%;协议级行为进一步与恶意分类相关,这是超越原始停滞时间的指纹信号。较短的诱导延迟(1.5秒)比较长的延迟(3秒)产生了更多的总参与度,这在两种协议中均观察到。这些结果将协议原生诱捕陷阱定位为OT/ICS环境中补丁不可行时的实用、低成本补充防御。

英文摘要

Operational technology systems face exposure to scanning and protocol-specific attack tools, where compromise risks disrupting physical processes rather than just data. Traditional OT defenses rely on blocking and filtering under strict patch constraints, while tarpitting delays scanners through sustained protocol-level interaction. Modbus TCP and IEC-104 carry no native authentication or integrity protection. Application-layer tarpitting, which stalls scanners inside a legitimate protocol exchange, has been studied for IT and IoT protocols, but not for OT/ICS, whose session semantics (state machines, exception codes) create stalling opportunities IT/IoT lack, and whose patch-constrained environments need exactly this kind of alternative defense. We present StallGrid, to our knowledge the first application-layer tarpits for OT/ICS, stalling scanners via Modbus Exception Codes \texttt{0x05}/\texttt{0x06} and prolonged residence in IEC-104's connected state machine. Five variants (three Modbus TCP, two IEC-104) ran simultaneously for 24 days online, logging 6,709 sessions, 2,039 cumulative per-tarpit unique IPs, and over 2,000 hours of accumulated connection engagement. GreyNoise enrichment attributes 87--97\% of stall time to malicious-tagged IPs, just 22--30\% of connecting addresses; protocol-level behavior further correlates with malicious classification, a fingerprinting signal beyond raw stall time. Shorter induced delay (1.5s) yielded more total engagement than longer delay (3s), observed across both protocols. These results position protocol-native tarpitting as a practical, low-cost complementary defense for OT/ICS environments where patching remains infeasible.

Comments20 pages of main body text lcns format, 1 page for 2 appendices sections, 3 pages for references. 10 figures, 7 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑